Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This document lists the outside companies Stripe uses to help run its services and explains what data goes to each one, where it is processed, and why. If Stripe adds a new company to the list that will process your data as a Business User, you have 30 days to object in writing — if you do nothing, Stripe treats that as your acceptance. All of these companies are only permitted to use your data to provide services to Stripe, not for their own purposes.
This document establishes Stripe's sub-processor disclosure framework, identifying the third-party service providers to which Stripe routes Business User, End Customer, Representative, and Visitor data, along with the data categories, geographic locations, and processing purposes for each. It sets out a time-limited objection right: Business Users may object in writing to a newly listed sub-processor within 30 days of the sub-processor page being updated, and inaction within that window constitutes deemed acceptance of the appointment. Sub-processors are contractually restricted to processing personal data solely for the purpose of providing services to Stripe and in accordance with Stripe's commitments to Business Users and applicable data protection laws. Regulatory data localization obligations require Stripe India Private Limited to store certain Indian payment transaction data on servers located in India, and Stripe Technology Company Limited in Ireland is identified as the data controller with primary responsibility for Personal Data processed outside the Americas.
As a Business User, the most direct effect of this document is the 30-day objection window: when Stripe updates its sub-processor page to add a new sub-processor that will process your data, you may object in writing within 30 days, and failure to do so is treated as acceptance of that appointment. Your data — along with End Customer and Visitor data — is shared with providers for purposes including sanctions screening (Ekata, Inc.), merchant monitoring (LegitScript, LLC), card printing (Idemia America Corp., receiving full card numbers and CVVs), AI-assisted support operations (Microsoft Corporation), and general infrastructure and site services (Google LLC, Amazon Internet Services Private Limited). All sub-processors are contractually limited to processing your data only to provide services to Stripe.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
Every distinct legal provision identified in this document. Featured provisions appear above with analysis.
Stripe has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle 30-Day Written Objection Right For New Sub-Processor and similar clauses.
Compare across platforms →Stripe's terms authorize fund reserves, payout withholding, and account termination. Here is what the agreement states and what business ow…
The Kickstarter-Stripe controversy reveals how payment processors, cloud providers, and AI platforms quietly shape downstream policy decisi…
Mastercard, Stripe, and Cloudflare are building payment infrastructure for autonomous AI agents. The governance layer is not keeping pace.
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.